// For flags

CVE-2024-36416

SuiteCRM v4 API Excessive log data DOS

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Attend
*SSVC
Descriptions

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a deprecated v4 API example with no log rotation allows denial of service by logging excessive data. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

SuiteCRM es una aplicación de software de gestión de relaciones con el cliente (CRM) de código abierto. Antes de las versiones 7.14.4 y 8.6.1, un ejemplo de API v4 obsoleto sin rotación de registros permitía la denegación de servicio al registrar datos excesivos. Las versiones 7.14.4 y 8.6.1 contienen una solución para este problema.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:Attend
Exploitation
None
Automatable
Yes
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2024-05-27 CVE Reserved
  • 2024-06-10 CVE Published
  • 2024-07-23 EPSS Updated
  • 2024-08-02 CVE Updated
  • 2024-08-02 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-779: Logging of Excessive Data
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Salesagility
Search vendor "Salesagility"
Suitecrm
Search vendor "Salesagility" for product "Suitecrm"
< 7.14.4
Search vendor "Salesagility" for product "Suitecrm" and version " < 7.14.4"
-
Affected
Salesagility
Search vendor "Salesagility"
Suitecrm
Search vendor "Salesagility" for product "Suitecrm"
>= 8.0.0 < 8.6.1
Search vendor "Salesagility" for product "Suitecrm" and version " >= 8.0.0 < 8.6.1"
-
Affected